summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Expand)Author
2025-07-09integrity/platform_certs: Allow loading of keys in the static key management ...Srish Srinivasan
2025-07-04tree-wide: s/struct fileattr/struct file_kattr/gChristian Brauner
2025-07-01selinux: implement inode_file_[g|s]etattr hooksAndrey Albershteyn
2025-07-01lsm: introduce new hooks for setting/getting inode fsxattrAndrey Albershteyn
2025-06-30smack: fix kernel-doc warnings for smk_import_valid_label()Konstantin Andreev
2025-06-27landlock: Fix warning from KUnit testsTingmao Wang
2025-06-24selinux: don't bother with selinuxfs_info_free() on failuresAl Viro
2025-06-24smack: fix bug: setting task label silently ignores input garbageKonstantin Andreev
2025-06-24smack: fix bug: unprivileged task can create labelsKonstantin Andreev
2025-06-23exec: Correct the permission check for unsafe execEric W. Biederman
2025-06-22smack: fix bug: invalid label of unix socket fileKonstantin Andreev
2025-06-22smack: always "instantiate" inode in smack_inode_init_security()Konstantin Andreev
2025-06-22smack: deduplicate xattr setting in smack_inode_init_security()Konstantin Andreev
2025-06-22smack: fix bug: SMACK64TRANSMUTE set on non-directoryKonstantin Andreev
2025-06-22smack: deduplicate "does access rule request transmutation"Konstantin Andreev
2025-06-19selinux: add __GFP_NOWARN to hashtab_init() allocationsPaul Moore
2025-06-19selinux: optimize selinux_inode_getattr/permission() based on neveraudit|perm...Stephen Smalley
2025-06-19selinux: introduce neveraudit typesStephen Smalley
2025-06-19selinux: change security_compute_sid to return the ssid or tsid on matchStephen Smalley
2025-06-17ipe: don't bother with removal of files in directory we'll be removingAl Viro
2025-06-17evm_secfs: clear securityfs interactionsAl Viro
2025-06-17ima_fs: get rid of lookup-by-dentry stuffAl Viro
2025-06-17ima_fs: don't bother with removal of files in directory we'll be removingAl Viro
2025-06-17apparmor: file never has NULL f_path.mntAl Viro
2025-06-17landlock: opened file never has a negative dentryAl Viro
2025-06-16selinux: fix selinux_xfrm_alloc_user() to set correct ctx_lenStephen Smalley
2025-06-16selinux: add a 5 second sleep to /sys/fs/selinux/userPaul Moore
2025-06-16lsm: trivial comment fixKalevi Kolttonen
2025-06-16ima: add a knob ima= to allow disabling IMA in kdump kernelBaoquan He
2025-06-11make securityfs_remove() remove the entire subtreeAl Viro
2025-06-11securityfs: pin filesystem only for objects directly in rootAl Viro
2025-06-11securityfs: don't pin dentries twice, once is enough...Al Viro
2025-06-11KEYS: Invert FINAL_PUT bitHerbert Xu
2025-05-31Merge tag 'gcc-minimum-version-6.16' of git://git.kernel.org/pub/scm/linux/ke...Linus Torvalds
2025-05-29Merge tag 'ipe-pr-20250527' of git://git.kernel.org/pub/scm/linux/kernel/git/...Linus Torvalds
2025-05-28Merge tag 'net-next-6.16' of git://git.kernel.org/pub/scm/linux/kernel/git/ne...Linus Torvalds
2025-05-28Merge tag 'selinux-pr-20250527' of git://git.kernel.org/pub/scm/linux/kernel/...Linus Torvalds
2025-05-28Merge tag 'lsm-pr-20250527' of git://git.kernel.org/pub/scm/linux/kernel/git/...Linus Torvalds
2025-05-28Merge tag 'integrity-v6.16' of git://git.kernel.org/pub/scm/linux/kernel/git/...Linus Torvalds
2025-05-28Merge tag 'Smack-for-6.16' of https://github.com/cschaufler/smack-nextLinus Torvalds
2025-05-28Merge tag 'hardening-v6.16-rc1' of git://git.kernel.org/pub/scm/linux/kernel/...Linus Torvalds
2025-05-27ipe: add errno field to IPE policy load auditingJasjiv Singh
2025-05-26Merge tag 'vfs-6.16-rc1.async.dir' of git://git.kernel.org/pub/scm/linux/kern...Linus Torvalds
2025-05-25apparmor: Document that label must be last member in struct aa_profileJohn Johansen
2025-05-25apparmor: make debug_values_table staticJohn Johansen
2025-05-25apparmor: force auditing of conflicting attachment execs from confinedRyan Lee
2025-05-25apparmor: include conflicting attachment info for confined ix/ux fallbackRyan Lee
2025-05-25apparmor: move the "conflicting profile attachments" infostr to a const decla...Ryan Lee
2025-05-25apparmor: force audit on unconfined exec if info is set by find_attachRyan Lee
2025-05-25apparmor: make all generated string array headers const char *constRyan Lee